Skip to main content

Modify the initial level of probability and impact of a risk created by risk analysis

Updated over 11 months ago

The probability of a risk is linked to the probability of the corresponding threat.

The impact of a risk is the maximum impact on the business stakes for the associated business values, taking into account the AICP requirements (Availability, Integrity, Confidentiality and Proof).

🔎 This definition of AICP requirements is important for applying the right threats to the right business values. That's why they are applied to threats and business stakes scales.

For example, the Reputations scale will be linked to the Integrity and Confidentiality in the AICP impacts.

According to these criteria, risks are created with an initial level of probability and impact.

⚠️ You cannot change these levels directly in the risk. You therefore need to adjust your risk analysis to obtain the necessary levels.

Any change in the risk analysis has an impact on all the risks derived from your risk analysis.

Adjust the initial impact level

Tenacy calculates the initial impact level using these 3 criteria:

  • the level of impact on business value

  • the type of impact of the threat

  • the business stakes scale

Let's take a concrete example to illustrate our need to adjust our risk analysis.

Here is the risk we want to adjust:

We want to adjust the initial impact from Medium to Low.

Our threat impact level is on Availability only according to the AICP matrix:

If we take the scale of business stakes below:

According to the threat, Availability is present at the Revenue level:

Our business value associated with this risk has these different levels of impact:

So, if we want to adjust the level of impact of our risk, we need to change the level of impact of the business value on Revenues from High to Moderate:

After this amendment, the risk analysis must be synchronized again.

Following this synchronization, the risk is updated to its initial impact level:

Adjust the initial probability level

We want to change the initial probability level of this same risk from Medium to Very Low:

We therefore need to go back to our risk analysis and change the probability level of the threat linked to the risk:

After the synchronization of our analysis, the risk is modified:

Did this answer your question?